CVE-2017-14919: Node.js

High severity, CVSS 7.5. EPSS: 8.3% chance of exploitation in the next 30 days.

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

Affected products

  • Node.js Node.js: version 4.8.2 only; version 4.8.3 only; version 4.8.4 only; version 6.10.2 only; version 6.10.3 only; version 6.11.0 only; …

Published 2017-10-30. Last modified 2026-07-14.